CVE-2015-7907: Honeywell Midas Black Firmware
High severity, CVSS 8.6. EPSS: 3.6% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
Affected products
- Honeywell Midas Black Firmware: up to and including 2.13b1
- Honeywell Midas Firmware: up to and including 1.13b1
Published 2015-12-21. Last modified 2026-06-17.